SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-21098

MEDIUM · CVSS 6.9 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Improper access control in the Link to Windows feature on affected Windows systems allows local attackers to connect to the PC without requiring user interaction, potentially leading to unauthorized access and data exposure. Organizations using this feature should prioritize patching to mitigate the risk of local exploitation. This vulnerability is particularly relevant for environments where physical access to devices is possible.

CVE
CVE-2026-21098
Severity
MEDIUM
CVSS
6.9
EPSS
0.10%
Windows

Original NVD Description

Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction.